CVE-2026-81930: CWE-522: Insufficiently Protected Credentials in Apache Software Foundation Apache Airflow Snowflake provider
Apache Airflow's Snowflake provider did not validate the connection's `account` and `region` fields before interpolating them into request URLs. The SQL API endpoint is built as `https://{account}.snowflakecomputing.com/api/v2/statements`, so an `account` value containing `/`, `?` or `#` demotes the intended domain to a path, query or fragment and leaves the attacker in control of the request host. The provider sends that request with an `Authorization: Bearer` header carrying a JWT minted from the connection's private key, or the configured OAuth or programmatic access token. A user who can edit the Snowflake connection but cannot read its secrets — Airflow gives connection-configuration users write-only access to stored credentials, and a `private_key_file` lives on the worker rather than in the connection — can therefore cause a valid token for the account to be delivered to a host of their choosing and replay it against the genuine Snowflake endpoint. No Dag-authoring ability is required: the attacker edits the connection and waits for an existing Dag to use it. The same unvalidated value was also used to build the OAuth token-request URL and the Cortex Agent base URL. Affects deployments where Snowflake connections are editable by users who are not trusted with the connection's credentials. Users are advised to upgrade to `apache-airflow-providers-snowflake` `6.18.0` or later, which rejects `account` and `region` values containing anything other than letters, digits, `.`, `_` and `-` in every URL the provider builds from them.
AI Analysis
Technical Summary
The Apache Airflow Snowflake provider did not validate the 'account' and 'region' fields before interpolating them into request URLs, such as the SQL API endpoint URL. Maliciously crafted 'account' values containing characters like '/', '?', or '#' can alter the intended domain to a path, query, or fragment, enabling an attacker to control the request host. Since the provider sends requests with an Authorization Bearer token (JWT or OAuth token) derived from connection credentials, an attacker with write-only access to the Snowflake connection configuration can cause a valid token to be sent to an attacker-controlled host and potentially replay it against the genuine Snowflake endpoint. This attack requires no DAG authoring privileges, only the ability to edit the connection. The vulnerability also affects OAuth token-request URLs and Cortex Agent base URLs built from these fields. The issue is resolved in apache-airflow-providers-snowflake version 6.18.0 by rejecting 'account' and 'region' values containing characters other than letters, digits, '.', '_', and '-'.
Potential Impact
An attacker with write-only access to Snowflake connection configurations can manipulate the 'account' and 'region' fields to redirect requests containing valid authorization tokens to attacker-controlled hosts. This could lead to unauthorized token exposure and replay attacks against the Snowflake API. The vulnerability does not require DAG authoring privileges and affects environments where connection editing is permitted without full credential access.
Mitigation Recommendations
Upgrade to apache-airflow-providers-snowflake version 6.18.0 or later, which enforces strict validation on 'account' and 'region' fields to allow only letters, digits, '.', '_', and '-'. This prevents malicious manipulation of request URLs. No other mitigation is required as the fix is official and available.
CVE-2026-81930: CWE-522: Insufficiently Protected Credentials in Apache Software Foundation Apache Airflow Snowflake provider
Description
Apache Airflow's Snowflake provider did not validate the connection's `account` and `region` fields before interpolating them into request URLs. The SQL API endpoint is built as `https://{account}.snowflakecomputing.com/api/v2/statements`, so an `account` value containing `/`, `?` or `#` demotes the intended domain to a path, query or fragment and leaves the attacker in control of the request host. The provider sends that request with an `Authorization: Bearer` header carrying a JWT minted from the connection's private key, or the configured OAuth or programmatic access token. A user who can edit the Snowflake connection but cannot read its secrets — Airflow gives connection-configuration users write-only access to stored credentials, and a `private_key_file` lives on the worker rather than in the connection — can therefore cause a valid token for the account to be delivered to a host of their choosing and replay it against the genuine Snowflake endpoint. No Dag-authoring ability is required: the attacker edits the connection and waits for an existing Dag to use it. The same unvalidated value was also used to build the OAuth token-request URL and the Cortex Agent base URL. Affects deployments where Snowflake connections are editable by users who are not trusted with the connection's credentials. Users are advised to upgrade to `apache-airflow-providers-snowflake` `6.18.0` or later, which rejects `account` and `region` values containing anything other than letters, digits, `.`, `_` and `-` in every URL the provider builds from them.
Affected software
Apache Software Foundation
Apache Airflow Snowflake provider
pkg:pypi/apache-airflow-providers-snowflakeRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Apache Airflow Snowflake provider did not validate the 'account' and 'region' fields before interpolating them into request URLs, such as the SQL API endpoint URL. Maliciously crafted 'account' values containing characters like '/', '?', or '#' can alter the intended domain to a path, query, or fragment, enabling an attacker to control the request host. Since the provider sends requests with an Authorization Bearer token (JWT or OAuth token) derived from connection credentials, an attacker with write-only access to the Snowflake connection configuration can cause a valid token to be sent to an attacker-controlled host and potentially replay it against the genuine Snowflake endpoint. This attack requires no DAG authoring privileges, only the ability to edit the connection. The vulnerability also affects OAuth token-request URLs and Cortex Agent base URLs built from these fields. The issue is resolved in apache-airflow-providers-snowflake version 6.18.0 by rejecting 'account' and 'region' values containing characters other than letters, digits, '.', '_', and '-'.
Potential Impact
An attacker with write-only access to Snowflake connection configurations can manipulate the 'account' and 'region' fields to redirect requests containing valid authorization tokens to attacker-controlled hosts. This could lead to unauthorized token exposure and replay attacks against the Snowflake API. The vulnerability does not require DAG authoring privileges and affects environments where connection editing is permitted without full credential access.
Mitigation Recommendations
Upgrade to apache-airflow-providers-snowflake version 6.18.0 or later, which enforces strict validation on 'account' and 'region' fields to allow only letters, digits, '.', '_', and '-'. This prevents malicious manipulation of request URLs. No other mitigation is required as the fix is official and available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-08-27T18:42:14.105Z
- State
- PUBLISHED
- Is Cloud Service
- true
Threat ID: 6abb9075f7a7c54106366ddb
Added to database: 09/29/2026, 10:18:29 UTC
Last enriched: 09/29/2026, 10:33:04 UTC
Last updated: 09/29/2026, 18:20:13 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.